This bug was fixed in the package linux - 3.2.0-48.74 --------------- linux (3.2.0-48.74) precise; urgency=low
[Steve Conklin] * Release Tracking Bug - LP: #1188206 [ Upstream Kernel Changes ] * iwlwifi: dvm: fix zero LQ CMD sending avoidance - LP: #1186932 linux (3.2.0-47.72) precise; urgency=low [Steve Conklin] * Release Tracking Bug - LP: #1187066 [ Upstream Kernel Changes ] * Revert "drm/i915: Fix detection of base of stolen memory" - LP: #1186572 * mmc: at91/avr32/atmel-mci: fix DMA-channel leak on module unload - LP: #1186572 * mmc: core: Fix bit width test failing on old eMMC cards - LP: #1186572 * mfd: adp5520: Restore mode bits on resume - LP: #1186572 * mmc: atmel-mci: pio hang on block errors - LP: #1186572 * x86: Eliminate irq_mis_count counted in arch_irq_stat - LP: #1186572 * ASoC: wm8994: missing break in wm8994_aif3_hw_params() - LP: #1186572 * ath9k: fix key allocation error handling for powersave keys - LP: #1186572 * nfsd4: don't allow owner override on 4.1 CLAIM_FH opens - LP: #1186572 * net/eth/ibmveth: Fixup retrieval of MAC address - LP: #1186572 * ext4: limit group search loop for non-extent files - LP: #1186572 * xen/vcpu/pvhvm: Fix vcpu hotplugging hanging. - LP: #1186572 * autofs - remove autofs dentry mount check - LP: #1186572 * ALSA: HDA: Fix Oops caused by dereference NULL pointer - LP: #1186572 * iscsi-target: Fix processing of OOO commands - LP: #1186572 * ACPICA: Fix possible buffer overflow during a field unit read operation - LP: #1186572 * B43: Handle DMA RX descriptor underrun - LP: #1186572 * mwifiex: clear is_suspended flag when interrupt is received early - LP: #1186572 * mwifiex: fix memory leak issue when driver unload - LP: #1186572 * mwifiex: fix setting of multicast filter - LP: #1186572 * cifs: only set ops for inodes in I_NEW state - LP: #1186572 * hp_accel: Ignore the error from lis3lv02d_poweron() at resume - LP: #1186572 * KVM: VMX: fix halt emulation while emulating invalid guest sate - LP: #1186572 * dm snapshot: fix error return code in snapshot_ctr - LP: #1186572 * dm bufio: avoid a possible __vmalloc deadlock - LP: #1186572 * tick: Cleanup NOHZ per cpu data on cpu down - LP: #1186572 * ACPI / EC: Restart transaction even when the IBF flag set - LP: #1186572 * drm/radeon: check incoming cliprects pointer - LP: #1186572 * staging: vt6656: use free_netdev instead of kfree - LP: #1186572 * hwmon: fix error return code in abituguru_probe() - LP: #1186572 * Kirkwood: Enable PCIe port 1 on QNAP TS-11x/TS-21x - LP: #1186572 * avr32: fix relocation check for signed 18-bit offset - LP: #1186572 * powerpc/pseries: Fix partition migration hang in stop_topology_update - LP: #1186572 * powerpc: Bring all threads online prior to migration/hibernation - LP: #1186572 * timer: Don't reinitialize the cpu base lock during CPU_UP_PREPARE - LP: #1186572 * tg3: Skip powering down function 0 on certain serdes devices - LP: #1186572 * USB: xHCI: override bogus bulk wMaxPacketSize values - LP: #1186572 * USB: UHCI: fix for suspend of virtual HP controller - LP: #1186572 * tracing: Fix leaks of filter preds - LP: #1186572 * usermodehelper: check subprocess_info->path != NULL - LP: #1186572 * drivers/char/ipmi: memcpy, need additional 2 bytes to avoid memory overflow - LP: #1186572 * ipmi: ipmi_devintf: compat_ioctl method fails to take ipmi_mutex - LP: #1186572 * USB: reset resume quirk needed by a hub - LP: #1186572 * usb: option: Add Telewell TW-LTE 4G - LP: #1186572 * USB: Blacklisted Cinterion's PLxx WWAN Interface - LP: #1186572 * USB: option: add device IDs for Dell 5804 (Novatel E371) WWAN card - LP: #1186572 * i2c: designware: always clear interrupts before enabling them - LP: #1186572 * USB: ftdi_sio: Add support for Newport CONEX motor drivers - LP: #1186572 * btrfs: don't stop searching after encountering the wrong item - LP: #1186572 * virtio_console: fix uapi header - LP: #1186572 * ARM: plat-orion: Fix num_resources and id for ge10 and ge11 - LP: #1186572 * USB: cxacru: potential underflow in cxacru_cm_get_array() - LP: #1186572 * TTY: Fix tty miss restart after we turn off flow-control - LP: #1186572 * sunrpc: clarify comments on rpc_make_runnable - LP: #1186572 * SUNRPC: Prevent an rpc_task wakeup race - LP: #1186572 * perf: net_dropmonitor: Fix trace parameter order - LP: #1186572 * perf: net_dropmonitor: Fix symbol-relative addresses - LP: #1186572 * ACPI / video: Add "Asus UL30A" to ACPI video detect blacklist - LP: #1186572 * fat: fix possible overflow for fat_clusters - LP: #1186572 * wait: fix false timeouts when using wait_event_timeout() - LP: #1186572 * mm: mmu_notifier: re-fix freed page still mapped in secondary MMU - LP: #1186572 * rapidio/tsi721: fix bug in MSI interrupt handling - LP: #1186572 * Fix for rapidio-tsi721-fix-bug-in-MSI-interrupt-handling * mm compaction: fix of improper cache flush in migration code - LP: #1186572 * mm/THP: use pmd_populate() to update the pmd with pgtable_t pointer - LP: #1186572 * drivers/block/brd.c: fix brd_lookup_page() race - LP: #1186572 * nilfs2: fix issue of nilfs_set_page_dirty() for page at EOF boundary - LP: #1186572 * random: fix accounting race condition with lockless irq entropy_count update - LP: #1186572 * ocfs2: goto out_unlock if ocfs2_get_clusters_nocache() failed in ocfs2_fiemap() - LP: #1186572 * mm/pagewalk.c: walk_page_range should avoid VM_PFNMAP areas - LP: #1186572 * xhci: Don't warn on empty ring for suspended devices. - LP: #1186572 * sched/debug: Limit sd->*_idx range on sysctl - LP: #1186572 * sched/debug: Fix sd->*_idx limit range avoiding overflow - LP: #1186572 * ipvs: ip_vs_sip_fill_param() BUG: bad check of return value - LP: #1186572 * pch_dma: Use GFP_ATOMIC because called from interrupt context - LP: #1186572 * drbd: fix for deadlock when using automatic split-brain-recovery - LP: #1186572 * x86, efivars: firmware bug workarounds should be in platform code - LP: #1186572 * efi: Export efi_query_variable_store() for efivars.ko - LP: #1186572 * x86,efi: Check max_size only if it is non-zero. - LP: #1186572 * x86,efi: Implement efi_no_storage_paranoia parameter - LP: #1186572 * tcp: force a dst refcount when prequeue packet - LP: #1186572 * 3c509.c: call SET_NETDEV_DEV for all device types (ISA/ISAPnP/EISA) - LP: #1186572 * net_sched: act_ipt forward compat with xtables - LP: #1186572 * bridge: fix race with topology change timer - LP: #1186572 * packet: tpacket_v3: do not trigger bug() on wrong header status - LP: #1186572 * 3c59x: fix freeing nonexistent resource on driver unload - LP: #1186572 * 3c59x: fix PCI resource management - LP: #1186572 * if_cablemodem.h: Add parenthesis around ioctl macros - LP: #1186572 * macvlan: fix passthru mode race between dev removal and rx path - LP: #1186572 * ipv6: do not clear pinet6 field - LP: #1186572 * xfrm6: release dev before returning error - LP: #1186572 * drivers/rtc/rtc-pcf2123.c: fix error return code in pcf2123_probe() - LP: #1186572 * mantis: fix silly crash case - LP: #1186572 * staging: comedi: prevent auto-unconfig of manually configured devices - LP: #1186572 * um: Serve io_remap_pfn_range() - LP: #1186572 * Linux 3.2.46 - LP: #1186572 linux (3.2.0-46.71) precise; urgency=low [Steve Conklin] * Release Tracking Bug - LP: #1186317 [ Upstream Kernel Changes ] * xen: implement apic ipi interface - LP: #1168350 * crypto: algif - suppress sending source address information in recvmsg - LP: #1172363 - CVE-2013-3076 * ax25: fix info leak via msg_name in ax25_recvmsg() - LP: #1172366 - CVE-2013-3223 * Bluetooth: fix possible info leak in bt_sock_recvmsg() - LP: #1172368 - CVE-2013-3224 * tipc: fix info leaks via msg_name in recv_msg/recv_stream - LP: #1172403 - CVE-2013-3235 * rose: fix info leak via msg_name in rose_recvmsg() - LP: #1172394 - CVE-2013-3234 * Bluetooth: RFCOMM - Fix missing msg_namelen update in rfcomm_sock_recvmsg() - LP: #1172369 - CVE-2013-3225 * atm: update msg_namelen in vcc_recvmsg() - LP: #1172365 - CVE-2013-3222 * aio: fix possible invalid memory access when DEBUG is enabled - LP: #1186055 * tracing: Use stack of calling function for stack tracer - LP: #1186055 * tracing: Fix stack tracer with fentry use - LP: #1186055 * tracing: Remove most or all of stack tracer stack size from stack_max_size - LP: #1186055 * tracing: Fix ftrace_dump() - LP: #1186055 * Wrong asm register contraints in the futex implementation - LP: #1186055 * Wrong asm register contraints in the kvm implementation - LP: #1186055 * cgroup: fix an off-by-one bug which may trigger BUG_ON() - LP: #1186055 * PCI / ACPI: Don't query OSC support with all possible controls - LP: #1186055 * drm/radeon: don't use get_engine_clock() on APUs - LP: #1186055 * drm/radeon: use frac fb div on RS780/RS880 - LP: #1186055 * Fix initialization of CMCI/CMCP interrupts - LP: #1186055 * sysfs: fix use after free in case of concurrent read/write and readdir - LP: #1186055 * usb/misc/appledisplay: Add 24" LED Cinema display - LP: #1186055 * nfsd: don't run get_file if nfs4_preprocess_stateid_op return error - LP: #1186055 * ext4/jbd2: don't wait (forever) for stale tid caused by wraparound - LP: #1186055 * jbd2: fix race between jbd2_journal_remove_checkpoint and ->j_commit_callback - LP: #1186055 * drm/i915: Add no-lvds quirk for Fujitsu Esprimo Q900 - LP: #1186055 * USB: add ftdi_sio USB ID for GDM Boost V1.x - LP: #1186055 * hrtimer: Add expiry time overflow check in hrtimer_interrupt - LP: #1186055 * hrtimer: Fix ktime_add_ns() overflow on 32bit architectures - LP: #1186055 * nfsd4: don't close read-write opens too soon - LP: #1186055 * tracing: Fix off-by-one on allocating stat->pages - LP: #1186055 * USB: option: add a D-Link DWM-156 variant - LP: #1186055 * tracing: Reset ftrace_graph_filter_enabled if count is zero - LP: #1186055 * tracing: Check return value of tracing_init_dentry() - LP: #1186055 * ALSA: usb: Add quirk for 192KHz recording on E-Mu devices - LP: #1186055 * ALSA: usb-audio: disable autopm for MIDI devices - LP: #1186055 * drm/radeon/evergreen+: don't enable HPD interrupts on eDP/LVDS - LP: #1186055 * drm/radeon: cleanup properly if mmio mapping fails - LP: #1186055 * serial_core.c: add put_device() after device_find_child() - LP: #1186055 * PCI/PM: Fix fallback to PCI_D0 in pci_platform_power_transition() - LP: #1186055 * wireless: regulatory: fix channel disabling race condition - LP: #1186055 * xen/smp: Fix leakage of timer interrupt line for every CPU online/offline. - LP: #1186055 * xen/smp/spinlock: Fix leakage of the spinlock interrupt line for every CPU online/offline - LP: #1186055 * xen/time: Fix kasprintf splat when allocating timer%d IRQ line. - LP: #1186055 * ASoC: max98088: Fix logging of hardware revision. - LP: #1186055 * usbfs: Always allow ctrl requests with USB_RECIP_ENDPOINT on the ctrl ep - LP: #1186055 * drm/i915: Workaround incoherence between fences and LLC across multiple CPUs - LP: #1186055 * drm/i915: ensure single initialization and cleanup of backlight device - LP: #1186055 * iwlwifi: dvm: don't send zeroed LQ cmd - LP: #1186055 * drm/i915: Fall back to bit banging mode for DVO transmitter detection - LP: #1186055 * LOCKD: Ensure that nlmclnt_block resets block->b_status after a server reboot - LP: #1186055 * ext4: fix Kconfig documentation for CONFIG_EXT4_DEBUG - LP: #1186055 * drm/radeon: fix hdmi mode enable on RS600/RS690/RS740 - LP: #1186055 * USB: ftdi_sio: correct ST Micro Connect Lite PIDs - LP: #1186055 * USB: serial: option: Added support Olivetti Olicard 145 - LP: #1186055 * usb-storage: CY7C68300A chips do not support Cypress ATACB - LP: #1186055 * i2c: xiic: must always write 16-bit words to TX_FIFO - LP: #1186055 * nfsd: Decode and send 64bit time values - LP: #1186055 * fbcon: when font is freed, clear also vc_font.data - LP: #1186055 * powerpc/spufs: Initialise inode->i_ino in spufs_new_inode() - LP: #1186055 * USB: ftdi_sio: enable two UART ports on ST Microconnect Lite - LP: #1186055 * ALSA: snd-usb: try harder to find USB_DT_CS_ENDPOINT - LP: #1186055 * gianfar: do not advertise any alarm capability. - LP: #1186055 * ALSA: usb-audio: Fix autopm error during probing - LP: #1186055 * clockevents: Set dummy handler on CPU_DEAD shutdown - LP: #1186055 * ixgbe: fix EICR write in ixgbe_msix_other - LP: #1186055 * powerpc: Add isync to copy_and_flush - LP: #1186055 * s390/memory hotplug: prevent offline of active memory increments - LP: #1186055 * mwifiex: Use pci_release_region() instead of a pci_release_regions() - LP: #1186055 * mwifiex: Call pci_release_region after calling pci_disable_device - LP: #1186055 * ARM: u300: fix ages old copy/paste bug - LP: #1186055 * fs/fscache/stats.c: fix memory leak - LP: #1186055 * drivers/rtc/rtc-cmos.c: don't disable hpet emulation on suspend - LP: #1186055 * md: bad block list should default to disabled. - LP: #1186055 * inotify: invalid mask should return a error number but not set it - LP: #1186055 * fs/dcache.c: add cond_resched() to shrink_dcache_parent() - LP: #1186055 * ipc: sysv shared memory limited to 8TiB - LP: #1186055 * drm/radeon: fix endian bugs in atom_allocate_fb_scratch() - LP: #1186055 * drm/radeon: fix possible segfault when parsing pm tables - LP: #1186055 * drm/radeon: fix handling of v6 power tables - LP: #1186055 * TTY: do not update atime/mtime on read/write - LP: #1186055 * TTY: fix atime/mtime regression - LP: #1186055 * tty: fix up atime/mtime mess, take three - LP: #1186055 * perf: Fix error return code - LP: #1186055 * perf/x86: Fix offcore_rsp valid mask for SNB/IVB - LP: #1186055 * s390: move dummy io_remap_pfn_range() to asm/pgtable.h - LP: #1186055 * vm: add vm_iomap_memory() helper function - LP: #1186055 * vm: convert snd_pcm_lib_mmap_iomem() to vm_iomap_memory() helper - LP: #1186055 * vm: convert fb_mmap to vm_iomap_memory() helper - LP: #1186055 * vm: convert HPET mmap to vm_iomap_memory() helper - LP: #1186055 * cbq: incorrect processing of high limits - LP: #1186055 * net IPv6 : Fix broken IPv6 routing table after loopback down-up - LP: #1186055 * net: count hw_addr syncs so that unsync works properly. - LP: #1186055 * atl1e: limit gso segment size to prevent generation of wrong ip length fields - LP: #1186055 * bonding: fix bonding_masters race condition in bond unloading - LP: #1186055 * bonding: IFF_BONDING is not stripped on enslave failure - LP: #1186055 * af_unix: If we don't care about credentials coallesce all messages - LP: #1186055 * netfilter: don't reset nf_trace in nf_reset() - LP: #1186055 * rtnetlink: Call nlmsg_parse() with correct header length - LP: #1186055 * tcp: incoming connections might use wrong route under synflood - LP: #1186055 * esp4: fix error return code in esp_output() - LP: #1186055 * net: sctp: sctp_auth_key_put: use kzfree instead of kfree - LP: #1186055 * tcp: call tcp_replace_ts_recent() from tcp_ack() - LP: #1186055 * caif: Fix missing msg_namelen update in caif_seqpkt_recvmsg() - LP: #1186055 * irda: Fix missing msg_namelen update in irda_recvmsg_dgram() - LP: #1186055 * iucv: Fix missing msg_namelen update in iucv_sock_recvmsg() - LP: #1186055 * llc: Fix missing msg_namelen update in llc_ui_recvmsg() - LP: #1186055 * netrom: fix info leak via msg_name in nr_recvmsg() - LP: #1186055 * netrom: fix invalid use of sizeof in nr_recvmsg() - LP: #1186055 * net: drop dst before queueing fragments - LP: #1186055 * sparc64: Fix race in TLB batch processing. - LP: #1186055 * r8169: fix 8168evl frame padding. - LP: #1186055 * drm/i915: Fix detection of base of stolen memory - LP: #1186055 * ixgbe: add missing rtnl_lock in PM resume path - LP: #1186055 * kernel/audit_tree.c: tree will leak memory when failure occurs in audit_trim_trees() - LP: #1186055 * powerpc: fix numa distance for form0 device tree - LP: #1186055 * r8169: fix vlan tag read ordering. - LP: #1186055 * x86/mm: account for PGDIR_SIZE alignment - LP: #1186055 * Linux 3.2.45 - LP: #1186055 -- Steve Conklin <sconk...@canonical.com> Thu, 06 Jun 2013 09:22:00 -0500 ** Changed in: linux (Ubuntu Precise) Status: New => Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3076 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3222 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3223 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3224 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3225 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3234 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3235 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1188206 Title: linux: 3.2.0-48.74 -proposed tracker To manage notifications about this bug go to: https://bugs.launchpad.net/kernel-sru-workflow/+bug/1188206/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs